Sr. Incident Response Engineer
Description
- Incident Detection and Response:
- Act as the Incident Commander when responding to cyber threats.
- Lead incident response efforts in real-time, managing communications and documentation throughout the incident lifecycle.
- Investigate, contain, and recover from security incidents, ensuring root cause analysis and threat remediation are completed.
- Technical Incident Response:
- Perform in-depth analysis of malware, network attacks, and other security breaches using digital forensic tools and techniques.
- Collect and preserve evidence in a forensically sound manner to support legal and regulatory requirements if needed.
- Automate incident response activities using scripting or other programming skills.
- Streamline technical response process and procedures
- Collaboration and Reporting:
- Collaborate with cross-functional teams, including IT, Product Engineering, Platform operations, and many other stakeholders, to mitigate risks and improve incident response processes.
- Prepare detailed reports on incident findings, root cause analysis, and remediation recommendations for technical and non-technical audiences.
- Continuously improve incident response playbooks, processes, and security controls.
- Security Improvements:
- Identify opportunities to enhance security posture through lessons learned from incidents, emerging threat landscapes, and evolving attack techniques.
- Work closely with Security and Engineering teams to implement stronger security measures.
- Conduct regular tabletop exercises and simulations to test the organization’s incident response readiness.
- Threat Intelligence and Research:
- Stay up-to-date on the latest security trends, vulnerabilities, attack vectors, and threat intelligence to enhance detection and response strategies.
- Actively contribute to knowledge sharing and mentoring within the security team.
- Bachelor’s degree in Computer Science, Information Security, or a related field or equivalent work experience.
- Excellent problem-solving, analytical skills, organizational skills, verbal and written communication, and time management skills. Ability to work well under pressure in a fast-paced environment.
- 3-5 years of experience in cybersecurity, with a focus on incident response, threat hunting, and forensics.
- Hands-on experience with SIEM tools (e.g., Splunk, QRadar), EDR solutions, firewalls, and IDS/IPS.
- Hands-on experience with network protocols, system architectures, and security tools.
- Proficiency in analyzing security event logs, malware reverse engineering, and digital forensics.
- Hands-on experience with scripting languages (Ruby, Bash, Python, etc.) for automation and incident response support.
- SANS GCIH, GCFE, GCFA or GREM certifications
- Other Digital forensics and Incident Response certifications.
Regular full-time employees are eligible for benefits - see here.
#LI-KB1
Why AppFolio
Grow | We enable a culture of high performance, where delivering results is recognized by opportunities for growth and compelling total rewards. Our challenging and meaningful work drive the growth of our business, and ourselves.
Learn | We partner with you to realize your potential by investing in you from the start. We're cultivating a team of big thinkers through coaching and mentorship with our best-in-class leaders, and giving you the time and tools to develop your skills.
Impact | We are creating a world where living in, investing in, managing, and supporting communities feels magical and effortless, freeing people to thrive. We do this by innovating with purpose while cultivating a culture of impact. We learn as much from each other as we do our customers and our communities.
Connect | We excel at hybrid work by fostering an environment that feels flexible, personal and connected, no matter where we are. We create space to fuel innovation and collaboration, and we come together to celebrate, connect, and succeed.
Paddle as One.
Learn more at appfolio.com/company/careers
Statement of Equal Opportunity
At AppFolio, we value diversity in backgrounds and perspectives and depend on it to drive our innovative culture. That’s why we’re a proud Equal Opportunity Employer, and we believe that our products, our teams, and our business are stronger because of it. This means that no matter what race, color, religion, sex, sexual orientation, gender identification, national origin, age, marital status, ancestry, physical or mental disability, or veteran status, you’re always welcome at AppFolio.